Here is the fresh combofix log. Just a heads up. I'm about to take a long trip so I won't be back for about 6 hours.
ComboFix 09-07-01.04 - OmNiExiZt 07/02/2009 10:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.592 [GMT -7:00]
Running from: c:\documents and settings\OmNiExiZt\Desktop\newname.exe
Command switches used :: c:\documents and settings\OmNiExiZt\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\WinRMSrv.msi
.
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.
2009-07-01 17:28 . 2009-07-01 17:28 -------- d-----w- c:\program files\Trend Micro
2009-06-29 00:01 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\OmNiExiZt\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-29 00:01 . 2009-06-29 00:01 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-28 23:58 . 2009-06-28 23:58 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-28 23:58 . 2009-06-29 00:47 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-28 23:58 . 2009-06-29 00:47 -------- d-----w- c:\program files\NOS
2009-06-23 18:34 . 2009-06-23 18:34 -------- d-----w- c:\documents and settings\Guest\Application Data\Protector Suite
2009-06-23 18:34 . 2009-06-23 18:34 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Symantec
2009-06-19 04:44 . 2009-06-27 05:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-19 04:44 . 2009-06-19 04:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-19 01:53 . 2009-06-19 01:53 1 ---h--w- c:\windows\bf23567.dat
2009-06-19 01:53 . 2009-06-19 01:53 2 ----a-w- c:\windows\0101120101465452.dat
2009-06-18 23:53 . 2009-07-02 07:20 -------- d-----w- c:\program files\driver
2009-06-18 17:20 . 2009-06-18 17:20 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-06-18 17:18 . 2008-04-13 17:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-06-18 17:18 . 2008-04-13 17:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-18 17:17 . 2004-09-29 19:15 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2009-06-18 17:17 . 2004-09-29 19:14 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2009-06-18 17:17 . 2004-09-29 19:12 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2009-06-18 17:17 . 2004-09-29 19:09 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2009-06-18 17:17 . 2004-09-29 19:09 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2009-06-18 17:17 . 2004-09-29 19:08 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2009-06-18 17:17 . 2009-06-18 17:17 -------- d-----w- c:\program files\HP
2009-06-18 17:16 . 2009-06-18 17:21 102262 ----a-w- c:\windows\hpoins05.dat
2009-06-18 17:14 . 2009-06-18 17:14 -------- d-----w- C:\Temp
2009-06-17 07:05 . 2009-07-02 07:20 -------- d-sh--r- c:\program files\Manson
2009-06-17 06:35 . 2009-06-17 06:35 -------- d-----w- c:\windows\Sun
2009-06-15 23:32 . 2009-06-15 23:32 -------- d-----w- c:\program files\uTorrent
2009-06-15 23:32 . 2009-06-28 06:58 -------- d-----w- c:\documents and settings\OmNiExiZt\Application Data\uTorrent
2009-06-15 04:23 . 2009-06-15 04:23 -------- d-----w- c:\windows\system32\LogFiles
2009-06-06 06:53 . 2009-06-06 06:53 -------- d-----w- c:\documents and settings\OmNiExiZt\Local Settings\Application Data\Identities
2009-06-05 06:21 . 2009-06-05 06:21 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-06-05 06:20 . 2009-06-05 06:21 -------- d-----w- c:\windows\SHELLNEW
2009-06-05 06:19 . 2009-06-05 06:19 -------- d-----w- c:\program files\Microsoft.NET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 18:45 . 2009-01-10 13:18 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-01 18:45 . 2009-01-10 13:18 -------- d-----w- c:\program files\Symantec
2009-07-01 18:45 . 2009-01-10 13:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-29 15:55 . 2005-10-01 09:57 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-28 07:47 . 2009-06-27 16:41 54 ----a-w- c:\documents and settings\OmNiExiZt\Application Data\MTC-savedfolder.dat
2009-06-27 04:16 . 2009-06-12 23:17 34 ----a-w- c:\documents and settings\OmNiExiZt\Application Data\MTC-savedinstructor.dat
2009-06-23 18:34 . 2009-06-23 18:15 51552 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-23 18:34 . 2009-06-23 18:15 128 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\fusioncache.dat
2009-06-18 17:51 . 2009-06-18 17:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-06-18 17:51 . 2009-06-18 17:51 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-06 10:11 . 2005-10-01 08:20 51552 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 03:21 . 2009-05-13 03:21 -------- d-----w- c:\program files\Microsoft Silverlight
2009-05-07 15:32 . 2005-09-30 17:46 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2005-09-30 17:46 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2005-09-30 17:46 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2005-09-30 17:46 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-09-30 17:46 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-02_07.31.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-02 08:01 . 2009-07-02 08:01 16384 c:\windows\Temp\Perflib_Perfdata_804.dat
+ 2009-06-06 05:42 . 2009-06-06 05:42 28160 c:\windows\Installer\52609.msi
+ 2009-06-06 05:42 . 2009-06-06 05:42 59904 c:\windows\Installer\525eb.msi
+ 2009-01-26 02:42 . 2009-01-26 02:42 25088 c:\windows\Installer\40fcb2.msi
+ 2009-01-26 02:42 . 2009-01-26 02:42 83456 c:\windows\Installer\40fc94.msi
+ 2009-06-18 17:21 . 2009-06-18 17:21 84992 c:\windows\Installer\3dd17a2.msi
+ 2009-05-13 03:21 . 2009-05-13 03:21 51712 c:\windows\Installer\29808.msi
+ 2009-06-29 00:01 . 2009-06-29 00:01 26624 c:\windows\Installer\109f92.msi
+ 2005-09-30 17:45 . 2004-08-10 12:00 66048 c:\windows\I386\WINNT32.MSI
+ 2005-09-30 17:48 . 2005-06-10 23:59 32256 c:\windows\Drivers\ATI NB Unified Driver\BIN\atiicdxx.msi
+ 2009-01-10 14:52 . 2004-07-17 19:41 366080 c:\windows\ServicePackFiles\i386\digreqex.msi
+ 2009-01-10 14:52 . 2004-07-17 19:41 863232 c:\windows\ServicePackFiles\i386\digopt.msi
+ 2005-10-01 08:09 . 2005-06-01 06:20 401104 c:\windows\Installer\iProData\mWlsSafe.msi
+ 2005-10-01 08:09 . 2005-06-01 06:19 400072 c:\windows\Installer\iProData\mProSafe.msi
+ 2005-10-01 08:09 . 2005-06-03 12:43 962560 c:\windows\Installer\iProData\mPfMgr.msi
+ 2009-03-07 05:51 . 2009-03-07 05:51 140288 c:\windows\Installer\c4037002.msi
+ 2005-10-01 09:58 . 2005-10-01 09:58 205824 c:\windows\Installer\691ed.msi
+ 2005-10-01 09:56 . 2005-10-01 09:56 246784 c:\windows\Installer\691cf.msi
+ 2009-01-27 06:08 . 2009-01-27 06:08 470528 c:\windows\Installer\62210ea.msi
+ 2009-06-06 05:43 . 2009-06-06 05:43 431104 c:\windows\Installer\5262f.msi
+ 2009-06-06 05:42 . 2009-06-06 05:42 152576 c:\windows\Installer\525fc.msi
+ 2009-01-26 02:42 . 2009-01-26 02:42 202752 c:\windows\Installer\40fca0.msi
+ 2009-01-26 02:42 . 2009-01-26 02:42 107008 c:\windows\Installer\40fc88.msi
+ 2009-01-26 02:41 . 2009-01-26 02:41 301056 c:\windows\Installer\40fc82.msi
+ 2009-06-18 17:21 . 2009-06-18 17:21 728064 c:\windows\Installer\3dd179c.msi
+ 2009-06-18 17:21 . 2009-06-18 17:21 136704 c:\windows\Installer\3dd1796.msi
+ 2005-10-01 09:17 . 2005-10-01 09:17 718848 c:\windows\Installer\2883f3.msi
+ 2005-10-01 09:14 . 2005-10-01 09:14 227840 c:\windows\Installer\271e8c.msi
+ 2008-06-11 21:02 . 2008-06-11 21:02 830464 c:\windows\Installer\2614eb2.msp
+ 2008-07-28 21:59 . 2008-07-28 21:59 180736 c:\windows\Installer\2601e33.msp
+ 2005-10-01 08:10 . 2005-10-01 08:10 477696 c:\windows\Installer\20520.msi
+ 2005-10-01 08:10 . 2005-10-01 08:10 676864 c:\windows\Installer\20514.msi
+ 2005-10-01 08:10 . 2005-10-01 08:10 398848 c:\windows\Installer\2050e.msi
+ 2005-10-01 08:10 . 2005-10-01 08:10 398336 c:\windows\Installer\20508.msi
+ 2005-10-01 08:10 . 2005-10-01 08:10 545792 c:\windows\Installer\20502.msi
+ 2005-10-01 08:09 . 2005-10-01 08:09 438272 c:\windows\Installer\204fc.msi
+ 2009-01-10 15:07 . 2009-01-10 15:07 432640 c:\windows\Installer\1c8848.msi
+ 2005-09-30 18:21 . 2005-09-30 18:21 264704 c:\windows\Installer\16478.msi
+ 2005-09-30 17:51 . 2005-06-01 06:20 401104 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mWlsSafe.msi
+ 2005-09-30 17:51 . 2005-06-01 06:19 400072 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mProSafe.msi
+ 2005-09-30 17:51 . 2005-06-03 12:43 962560 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mPfMgr.msi
+ 2005-09-30 17:46 . 2004-08-10 12:00 1326080 c:\windows\system32\webfldrs.msi
+ 2009-01-10 14:53 . 2004-08-10 12:00 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2009-01-10 14:52 . 2004-07-17 19:41 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi
+ 2007-05-25 20:08 . 2007-05-25 20:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2005-10-01 08:09 . 2005-06-01 06:20 8445440 c:\windows\Installer\iProData\mXML.msi
+ 2005-10-01 08:09 . 2005-06-03 11:19 1264640 c:\windows\Installer\iProData\mMHouse.msi
+ 2005-10-01 08:09 . 2005-06-03 12:31 2522624 c:\windows\Installer\iProData\mDriver.msi
+ 2005-10-01 08:09 . 2005-06-03 10:54 3161088 c:\windows\Installer\iProData\mCore.msi
+ 2005-10-26 21:59 . 2005-10-26 21:59 2883072 c:\windows\Installer\f1a7b8.msp
+ 2009-04-07 00:00 . 2009-04-07 00:00 5518336 c:\windows\Installer\f1a7a2.msp
+ 2009-06-29 15:55 . 2009-06-29 15:55 3938816 c:\windows\Installer\e7a88.msi
+ 2005-10-01 09:59 . 2005-10-01 09:59 1206784 c:\windows\Installer\691f1.msi
+ 2005-10-01 09:48 . 2005-10-01 09:48 1880576 c:\windows\Installer\691c9.msi
+ 2005-10-01 09:42 . 2005-10-01 09:42 1239552 c:\windows\Installer\691c3.msi
+ 2005-10-01 09:39 . 2005-10-01 09:39 5864960 c:\windows\Installer\691ba.msp
+ 2009-06-05 06:21 . 2009-06-05 06:21 5922816 c:\windows\Installer\2d56b8.msi
+ 2009-01-15 10:35 . 2009-01-15 10:35 4830720 c:\windows\Installer\2980f.msp
+ 2005-10-01 08:15 . 2005-10-01 08:15 3443712 c:\windows\Installer\28961.msi
+ 2008-06-11 22:05 . 2008-06-11 22:05 9994240 c:\windows\Installer\2614f82.msp
+ 2009-05-01 22:49 . 2009-05-01 22:49 4328960 c:\windows\Installer\2614f68.msp
+ 2008-10-23 05:48 . 2008-10-23 05:48 7672832 c:\windows\Installer\2614f3b.msp
+ 2008-01-31 17:30 . 2008-01-31 17:30 9947648 c:\windows\Installer\2614f0f.msp
+ 2008-01-14 23:53 . 2008-01-14 23:53 5213696 c:\windows\Installer\2614ef2.msp
+ 2008-10-25 16:15 . 2008-10-25 16:15 6227456 c:\windows\Installer\2614edd.msp
+ 2007-11-08 18:42 . 2007-11-08 18:42 4158464 c:\windows\Installer\2614e9d.msp
+ 2009-03-05 22:40 . 2009-03-05 22:40 6819840 c:\windows\Installer\2614e80.msp
+ 2009-05-12 20:01 . 2009-05-12 20:01 6818816 c:\windows\Installer\2601e78.msp
+ 2008-04-01 21:33 . 2008-04-01 21:33 5479936 c:\windows\Installer\2601e62.msp
+ 2009-05-28 19:32 . 2009-05-28 19:32 5518848 c:\windows\Installer\2601e49.msp
+ 2009-04-24 00:57 . 2009-04-24 00:57 7672832 c:\windows\Installer\2601e1e.msp
+ 2005-10-01 08:10 . 2005-10-01 08:10 7137792 c:\windows\Installer\2051a.msi
+ 2009-01-10 13:26 . 2009-01-10 13:26 1098240 c:\windows\Installer\1407c.msi
+ 2009-01-10 13:26 . 2009-01-10 13:26 1104896 c:\windows\Installer\13ff3.msi
+ 2009-01-10 13:25 . 2009-01-10 13:25 1096704 c:\windows\Installer\13f6b.msi
+ 2009-01-10 13:25 . 2009-01-10 13:25 1569792 c:\windows\Installer\13f5f.msi
+ 2009-01-10 13:23 . 2009-01-10 13:23 2657792 c:\windows\Installer\13f57.msi
+ 2009-01-10 13:14 . 2009-01-10 13:14 1255936 c:\windows\Installer\13e8f.msi
+ 2009-01-10 13:09 . 2009-01-10 13:09 4806656 c:\windows\Installer\13e71.msi
+ 2005-09-30 17:51 . 2005-06-01 06:20 8445440 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mXML.msi
+ 2005-09-30 17:51 . 2005-06-03 11:19 1264640 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mMHouse.msi
+ 2005-09-30 17:51 . 2005-06-03 12:31 2522624 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mDriver.msi
+ 2005-09-30 17:51 . 2005-06-03 10:54 3161088 c:\windows\Drivers\Intel Pro 2915ABG_2200BG\iProData\mCore.msi
+ 2005-09-30 17:50 . 2005-07-07 01:29 2658304 c:\windows\Drivers\Bluetooth driver\BtSwInst.msi
+ 2009-01-10 13:41 . 2005-10-01 09:14 11339776 c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150030}\J2SE Runtime Environment 5.0 Update 3.msi
+ 2005-10-01 08:17 . 2005-10-01 08:17 15016960 c:\windows\Installer\413c0.msi
+ 2005-10-01 09:16 . 2005-10-01 09:16 19210240 c:\windows\Installer\2883ed.msp
+ 2008-07-30 15:50 . 2008-07-30 15:50 12506112 c:\windows\Installer\2614f51.msp
+ 2008-06-04 20:29 . 2008-06-04 20:29 16905728 c:\windows\Installer\2614f25.msp
+ 2008-01-14 22:24 . 2008-01-14 22:24 10721280 c:\windows\Installer\2614ec7.msp
+ 2009-01-10 15:09 . 2009-01-10 15:09 15256576 c:\windows\Installer\1c8860.msp
+ 2009-01-10 13:01 . 2009-01-10 13:01 19235840 c:\windows\Installer\13e6b.msi
+ 2009-01-10 13:01 . 2009-01-10 13:01 19214848 c:\windows\Installer\13e6a.msi
+ 2005-09-30 17:47 . 2005-07-20 22:43 15020544 c:\windows\Drivers\ATI NB Unified Driver\ACE\ATI Catalyst Control Center.msi
+ 2007-07-27 16:03 . 2007-07-27 16:03 119977472 c:\windows\Installer\f1a78b.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-04-16 172032]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-29 344064]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-14 45056]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-07-20 32768]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-05-15 184320]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-01-14 151552]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2005-01-21 167936]
"Biomenu"="c:\program files\Protector Suite QL\menusw.exe" [2005-07-26 1073664]
"PartSeal"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - c:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-7-20 32768]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-6-21 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-07-26 03:06 39936 ----a-w- c:\windows\system32\fusstub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 00:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli fusstub
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:driver
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [10/4/2004 5:47 AM 98304]
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [7/25/2005 8:08 PM 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [7/25/2005 8:08 PM 33024]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [10/4/2004 4:40 AM 118784]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [3/19/2009 10:52 PM 33792]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [9/30/2005 10:52 AM 214272]
S3 fa410;NETGEAR FA410TX Fast Ethernet PC Card Driver;c:\windows\system32\drivers\fa410nd5.sys [9/30/2005 4:07 AM 24618]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
.
Contents of the 'Scheduled Tasks' folder
2009-01-10 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-09-30 00:12]
2009-01-10 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-09-30 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.sony.com/vaiopeople
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\OmNiExiZt\Application Data\Mozilla\Firefox\Profiles\96667qnt.default\
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-02 10:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\passport.dll
c:\program files\Protector Suite QL\BhTcAll.dll
c:\program files\Protector Suite QL\BhDevTfm.dll
c:\program files\Protector Suite QL\AlgVer.dll
c:\program files\Protector Suite QL\TCBioLib.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\VESWinlogon.dll
c:\program files\Protector Suite QL\mysafe.dll
c:\program files\Protector Suite QL\config.dll
- - - - - - - > 'lsass.exe'(932)
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
.
Completion time: 2009-07-02 10:11
ComboFix-quarantined-files.txt 2009-07-02 17:11
ComboFix2.txt 2009-07-02 07:36
Pre-Run: 57,313,341,440 bytes free
Post-Run: 57,291,554,816 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /PAE
293 --- E O F --- 2009-06-11 10:05